From 55f922200a6d47611ceff89bdf98c2fda017191b Mon Sep 17 00:00:00 2001 From: Zhang Hai Peng Date: Tue, 2 Jun 2026 10:14:29 +0800 Subject: [PATCH 1/9] fix(bt): Add default BLE controller funcs reset enable (cherry picked from commit 7c1cb4b29637e5124f1c426203a52a61f7a0e117) Co-authored-by: zhanghaipeng --- components/bt/controller/esp32c3/Kconfig.in | 9 +++++++++ components/bt/controller/esp32c3/bt.c | 5 +++++ components/bt/include/esp32c3/include/esp_bt.h | 18 ++++++++++++++++-- 3 files changed, 30 insertions(+), 2 deletions(-) diff --git a/components/bt/controller/esp32c3/Kconfig.in b/components/bt/controller/esp32c3/Kconfig.in index d6acc873092..25d4a0ffd5c 100644 --- a/components/bt/controller/esp32c3/Kconfig.in +++ b/components/bt/controller/esp32c3/Kconfig.in @@ -2,6 +2,15 @@ config BT_CTRL_MODE_EFF int default 1 +config BT_CTRL_CHECK_CONFIG_EFF + int + default 1 + help + Marker that controller Kconfig is active (always set in sdkconfig). + Must not be unset in normal IDF builds. Controller-only integrations + that do not export this symbol rely on esp_bt.h to apply compile-time + defaults for missing BLE feature CONFIG_* names. + config BT_CTRL_BLE_MAX_ACT int "BLE Max Instances" default 6 diff --git a/components/bt/controller/esp32c3/bt.c b/components/bt/controller/esp32c3/bt.c index 8e3a94b023e..72acdcfbcf5 100644 --- a/components/bt/controller/esp32c3/bt.c +++ b/components/bt/controller/esp32c3/bt.c @@ -1867,6 +1867,11 @@ esp_err_t esp_bt_controller_init(esp_bt_controller_config_t *cfg) ESP_LOGI(BT_LOG_TAG, "BT controller compile version [%s]", btdm_controller_get_compile_version()); +#ifndef CONFIG_BT_CTRL_CHECK_CONFIG_EFF + ESP_LOGW(BT_LOG_TAG, "CONFIG_BT_CTRL_CHECK_CONFIG_EFF is not defined; " + "using compile-time default BLE controller feature options"); +#endif + #if (CONFIG_BT_CTRL_RUN_IN_FLASH_ONLY) ESP_LOGI(BT_LOG_TAG,"Put all controller code in flash"); #endif diff --git a/components/bt/include/esp32c3/include/esp_bt.h b/components/bt/include/esp32c3/include/esp_bt.h index 48e939be06b..941df1925bd 100644 --- a/components/bt/include/esp32c3/include/esp_bt.h +++ b/components/bt/include/esp32c3/include/esp_bt.h @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2015-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2015-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -268,7 +268,21 @@ typedef void (* esp_bt_hci_tl_callback_t) (void *arg, uint8_t status); #define BT_CTRL_RUN_IN_FLASH_ONLY (0) #endif - +/* + * Only when CONFIG_BT_CTRL_CHECK_CONFIG_EFF is absent: this build does not + * run controller Kconfig, so missing CONFIG_BT_CTRL_BLE_* means "use default", + * not "disabled". When the symbol is defined (normal IDF sdkconfig), Kconfig + * is authoritative: bool=n leaves CONFIG_BT_CTRL_BLE_* undefined and must + * not be overridden here. + */ +#ifndef CONFIG_BT_CTRL_CHECK_CONFIG_EFF +#define CONFIG_BT_CTRL_BLE_ADV 1 +#define CONFIG_BT_CTRL_BLE_SCAN 1 +#define CONFIG_BT_CTRL_DTM_ENABLE 1 +#define CONFIG_BT_CTRL_BLE_MASTER 1 +#define CONFIG_BT_CTRL_BLE_SECURITY_ENABLE 1 +#define CONFIG_BT_CTRL_BLE_MIN_CONN_INTERVAL_ENABLE 1 +#endif /* !CONFIG_BT_CTRL_CHECK_CONFIG_EFF */ #if defined(CONFIG_BT_CTRL_DTM_ENABLE) #define BT_CTRL_DTM_ENABLE CONFIG_BT_CTRL_DTM_ENABLE From 124debe5d518c05ddf843dd5b70aa0a4887190b1 Mon Sep 17 00:00:00 2001 From: Zhang Hai Peng Date: Tue, 2 Jun 2026 10:23:42 +0800 Subject: [PATCH 2/9] fix(ble/bluedroid): Ensure HIGH_DUTY_ADV_INTERVAL config is applied in stack (cherry picked from commit 82c5c1fef3818bee736efb5b8f5b98bb1a693b24) Co-authored-by: zhanghaipeng --- components/bt/host/bluedroid/api/include/api/esp_bt_defs.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/components/bt/host/bluedroid/api/include/api/esp_bt_defs.h b/components/bt/host/bluedroid/api/include/api/esp_bt_defs.h index bd4b2c7e763..b6573c4de65 100644 --- a/components/bt/host/bluedroid/api/include/api/esp_bt_defs.h +++ b/components/bt/host/bluedroid/api/include/api/esp_bt_defs.h @@ -210,7 +210,7 @@ typedef uint8_t esp_link_key[ESP_BT_OCTET16_LEN]; /* Link Key */ /// Default GATT interface id #define ESP_DEFAULT_GATT_IF 0xff -#if BLE_HIGH_DUTY_ADV_INTERVAL +#if CONFIG_BT_BLE_HIGH_DUTY_ADV_INTERVAL #define ESP_BLE_PRIM_ADV_INT_MIN 0x000008 /*!< Minimum advertising interval for undirected and low duty cycle directed advertising */ #else #define ESP_BLE_PRIM_ADV_INT_MIN 0x000020 /*!< Minimum advertising interval for undirected and low duty cycle directed advertising */ From 89124f6c2aa0ecced531005fb7466beb5caa4a49 Mon Sep 17 00:00:00 2001 From: Zhang Hai Peng Date: Tue, 2 Jun 2026 10:23:42 +0800 Subject: [PATCH 3/9] doc(ble/bluedroid): clarify callback notes to avoid time-consuming ops (cherry picked from commit 4590b4bb34d897360049ad7cf4f8150805c878e0) Co-authored-by: zhanghaipeng --- .../bt/host/bluedroid/api/include/api/esp_gap_ble_api.h | 6 +++++- .../bt/host/bluedroid/api/include/api/esp_gattc_api.h | 6 +++++- .../bt/host/bluedroid/api/include/api/esp_gatts_api.h | 8 ++++++-- 3 files changed, 16 insertions(+), 4 deletions(-) diff --git a/components/bt/host/bluedroid/api/include/api/esp_gap_ble_api.h b/components/bt/host/bluedroid/api/include/api/esp_gap_ble_api.h index da5df368a1a..4fc217c36c4 100644 --- a/components/bt/host/bluedroid/api/include/api/esp_gap_ble_api.h +++ b/components/bt/host/bluedroid/api/include/api/esp_gap_ble_api.h @@ -2902,7 +2902,11 @@ typedef void (* esp_gap_ble_cb_t)(esp_gap_ble_cb_event_t event, esp_ble_gap_cb_p * * @param[in] callback: callback function * - * @note Avoid performing time-consuming operations within the callback functions. + * @note Do NOT perform time-consuming operations in the callback. Time-consuming operations + * include: taking semaphores that may block for a long time (e.g. xSemaphoreTake with + * long timeout or portMAX_DELAY), blocking delays (e.g. vTaskDelay), and flash + * read/write/erase. Such operations may block the Bluetooth stack and lead to + * instability or deadlock. Defer heavy work to a separate task if needed. * * @return * - ESP_OK : success diff --git a/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h b/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h index 70953609ee6..9129edb6f4d 100644 --- a/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h +++ b/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h @@ -280,7 +280,11 @@ typedef void (* esp_gattc_cb_t)(esp_gattc_cb_event_t event, esp_gatt_if_t gattc_ * * @param[in] callback The pointer to the application callback function * - * @note Avoid performing time-consuming operations within the callback functions. + * @note Do NOT perform time-consuming operations in the callback. Time-consuming operations + * include: taking semaphores that may block for a long time (e.g. xSemaphoreTake with + * long timeout or portMAX_DELAY), blocking delays (e.g. vTaskDelay), and flash + * read/write/erase. Such operations may block the Bluetooth stack and lead to + * instability or deadlock. Defer heavy work to a separate task if needed. * * @return * - ESP_OK: Success diff --git a/components/bt/host/bluedroid/api/include/api/esp_gatts_api.h b/components/bt/host/bluedroid/api/include/api/esp_gatts_api.h index 642222104ad..875ddbc9a11 100644 --- a/components/bt/host/bluedroid/api/include/api/esp_gatts_api.h +++ b/components/bt/host/bluedroid/api/include/api/esp_gatts_api.h @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2015-2024 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2015-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -283,7 +283,11 @@ typedef void (* esp_gatts_cb_t)(esp_gatts_cb_event_t event, esp_gatt_if_t gatts_ * * @param[in] callback The pointer to the application callback function * - * @note Avoid performing time-consuming operations within the callback functions. + * @note Do NOT perform time-consuming operations in the callback. Time-consuming operations + * include: taking semaphores that may block for a long time (e.g. xSemaphoreTake with + * long timeout or portMAX_DELAY), blocking delays (e.g. vTaskDelay), and flash + * read/write/erase. Such operations may block the Bluetooth stack and lead to + * instability or deadlock. Defer heavy work to a separate task if needed. * * @return * - ESP_OK: Success From f2428fc028520d8404d6143e2a4d762844799a1f Mon Sep 17 00:00:00 2001 From: Zhang Hai Peng Date: Tue, 2 Jun 2026 10:23:43 +0800 Subject: [PATCH 4/9] feat(ble/bluedroid): add auto-setting for is_aux parameter in esp_ble_gattc_enh_open (cherry picked from commit 1a9f2af505465cffac57343c6e75244409d6d868) Co-authored-by: zhanghaipeng --- .../bt/host/bluedroid/api/esp_gattc_api.c | 2 +- .../bluedroid/api/include/api/esp_gatt_defs.h | 12 +++++++++- .../bluedroid/api/include/api/esp_gattc_api.h | 20 +++++++++++++---- .../bt/host/bluedroid/stack/l2cap/l2c_ble.c | 22 ++++++++++++++++++- 4 files changed, 49 insertions(+), 7 deletions(-) diff --git a/components/bt/host/bluedroid/api/esp_gattc_api.c b/components/bt/host/bluedroid/api/esp_gattc_api.c index 0e2befd18d7..2a61abeb053 100644 --- a/components/bt/host/bluedroid/api/esp_gattc_api.c +++ b/components/bt/host/bluedroid/api/esp_gattc_api.c @@ -93,7 +93,7 @@ esp_err_t esp_ble_gattc_enh_open(esp_gatt_if_t gattc_if, esp_ble_gatt_creat_conn memcpy(arg.open.remote_bda, creat_conn_params->remote_bda, ESP_BD_ADDR_LEN); arg.open.remote_addr_type = creat_conn_params->remote_addr_type; arg.open.is_direct = creat_conn_params->is_direct; - arg.open.is_aux= creat_conn_params->is_aux; + arg.open.is_aux = creat_conn_params->is_aux; #if (BT_BLE_FEAT_PAWR_EN == TRUE) arg.open.is_pawr_synced = false; arg.open.adv_handle = 0xFF; diff --git a/components/bt/host/bluedroid/api/include/api/esp_gatt_defs.h b/components/bt/host/bluedroid/api/include/api/esp_gatt_defs.h index 688366a9b0c..b8051625eef 100644 --- a/components/bt/host/bluedroid/api/include/api/esp_gatt_defs.h +++ b/components/bt/host/bluedroid/api/include/api/esp_gatt_defs.h @@ -687,7 +687,17 @@ typedef struct { esp_bd_addr_t remote_bda; /*!< The Bluetooth address of the remote device */ esp_ble_addr_type_t remote_addr_type; /*!< Address type of the remote device */ bool is_direct; /*!< Direct connection or background auto connection(by now, background auto connection is not supported */ - bool is_aux; /*!< Set to true for BLE 5.0 or higher to enable auxiliary connections; set to false for BLE 4.2 or lower. */ + bool is_aux; /*!< Determines whether to use BLE 5.0 or BLE 4.2 create connection interface. + - If set to true, the BLE 5.0 interface (extended connection) will be used. + - If set to false, the BLE 4.2 interface (legacy connection) will be used. + - Note: When connecting to a legacy advertising device using BLE 5.0 interface, is_aux should be set to true. + - Auto-setting (handled in L2CAP layer): The system will automatically set this parameter based on the enabled BLE features: + * If only BLE 4.2 feature is enabled, is_aux will be automatically set to false. + * If only BLE 5.0 feature is enabled, is_aux will be automatically set to true. + * If both BLE 4.2 and BLE 5.0 features are enabled (not recommended), the stack will automatically + infer whether to use BLE 5.0 or BLE 4.2 interface based on previously used APIs. + Otherwise, the user-specified value will be used. + - Note: It is strongly recommended NOT to enable both BLE 4.2 and BLE 5.0 features simultaneously. */ esp_ble_addr_type_t own_addr_type; /*!< Specifies the address type used in the connection request. Set to 0xFF if the address type is unknown. */ esp_ble_phy_mask_t phy_mask; /*!< Indicates which PHY connection parameters will be used. When is_aux is false, only the connection params for 1M PHY can be specified */ const esp_ble_conn_params_t *phy_1m_conn_params; /*!< Connection parameters for the LE 1M PHY */ diff --git a/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h b/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h index 9129edb6f4d..9f662b6c97c 100644 --- a/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h +++ b/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h @@ -334,10 +334,22 @@ esp_err_t esp_ble_gattc_app_unregister(esp_gatt_if_t gattc_if); * * @note * 1. Do not enable `BT_BLE_42_FEATURES_SUPPORTED` and `BT_BLE_50_FEATURES_SUPPORTED` in the menuconfig simultaneously. - * 1. The function always triggers `ESP_GATTC_CONNECT_EVT` and `ESP_GATTC_OPEN_EVT`. - * 2. When the device acts as GATT server, besides the above two events, this function triggers `ESP_GATTS_CONNECT_EVT` as well. - * 3. This function will establish an ACL connection as a Central and a virtual connection as a GATT Client. If the ACL connection already exists, it will create a virtual connection only. - + * 2. The function always triggers `ESP_GATTC_CONNECT_EVT` and `ESP_GATTC_OPEN_EVT`. + * 3. When the device acts as GATT server, besides the above two events, this function triggers `ESP_GATTS_CONNECT_EVT` as well. + * 4. This function will establish an ACL connection as a Central and a virtual connection as a GATT Client. If the ACL connection already exists, it will create a virtual connection only. + * 5. The `is_aux` parameter in `esp_gatt_creat_conn_params_t` determines which connection interface to use: + * - If `is_aux` is true, the BLE 5.0 extended connection interface will be used. + * - If `is_aux` is false, the BLE 4.2 interface (legacy connection) will be used. + * - When connecting to a legacy advertising device using BLE 5.0 interface, `is_aux` should be set to true. + * 6. Auto-setting of `is_aux` parameter (handled in L2CAP layer): + * - If only BLE 4.2 feature is enabled, `is_aux` will be automatically set to false. + * - If only BLE 5.0 feature is enabled, `is_aux` will be automatically set to true. + * - If both BLE 4.2 and BLE 5.0 features are enabled (not recommended): + * * The stack will automatically infer whether to use BLE 5.0 or BLE 4.2 interface + * based on previously used APIs. + * * Otherwise, the user-specified value will be used. + * - Note: It is strongly recommended NOT to enable both BLE 4.2 and BLE 5.0 features + * simultaneously in menuconfig. * * @param[in] gattc_if: GATT client access interface. * @param[in] esp_gatt_create_conn: Pointer to the structure containing connection parameters. diff --git a/components/bt/host/bluedroid/stack/l2cap/l2c_ble.c b/components/bt/host/bluedroid/stack/l2cap/l2c_ble.c index 65d4e643b06..d4acd714ae8 100644 --- a/components/bt/host/bluedroid/stack/l2cap/l2c_ble.c +++ b/components/bt/host/bluedroid/stack/l2cap/l2c_ble.c @@ -1034,7 +1034,27 @@ BOOLEAN l2cble_init_direct_conn (tL2C_LCB *p_lcb) } } - if (!p_lcb->is_aux) { + // Auto-set is_aux based on BLE feature support + bool is_aux = p_lcb->is_aux; +#if (BLE_42_FEATURE_SUPPORT == TRUE) && (BLE_50_FEATURE_SUPPORT == FALSE) + if (is_aux) { + L2CAP_TRACE_WARNING("is_aux auto-set to false (BLE 4.2 only)"); + is_aux = false; + } +#elif (BLE_42_FEATURE_SUPPORT == FALSE) && (BLE_50_FEATURE_SUPPORT == TRUE) + if (!is_aux) { + L2CAP_TRACE_WARNING("is_aux auto-set to true (BLE 5.0 only)"); + is_aux = true; + } +#else + extern bool btm_ble_inter_get(void); + if (btm_ble_inter_get() && (!is_aux)) { + L2CAP_TRACE_WARNING("is_aux auto-set to true (BLE 5.0 API used)"); + is_aux = true; + } +#endif + + if (!is_aux) { if (!btsnd_hcic_ble_create_ll_conn (scan_int, /* UINT16 scan_int */ scan_win, /* UINT16 scan_win */ FALSE, /* UINT8 white_list */ From 8bd3e97b5094046fc505dd3698fbf6702348da19 Mon Sep 17 00:00:00 2001 From: Zhang Hai Peng Date: Tue, 2 Jun 2026 10:23:43 +0800 Subject: [PATCH 5/9] docs(bt/bluedroid): add usage note for esp_ble_get_cur_sendable_packets_num (cherry picked from commit 27fc241384784d9bc124c4a6b7e102506636edbe) Co-authored-by: zhanghaipeng --- components/bt/host/bluedroid/api/esp_gatt_common_api.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/components/bt/host/bluedroid/api/esp_gatt_common_api.c b/components/bt/host/bluedroid/api/esp_gatt_common_api.c index 9254b8d87af..d3348d5a450 100644 --- a/components/bt/host/bluedroid/api/esp_gatt_common_api.c +++ b/components/bt/host/bluedroid/api/esp_gatt_common_api.c @@ -64,6 +64,9 @@ uint16_t esp_ble_get_sendable_packets_num (void) /** * @brief This function is used to query the number of available buffers for the current connection. * When you need to query the current available buffer number, it is recommended to use this API. + * + * @note This API can only be called when a direct connection exists. + * * @param[in] conn_id: current connection id. * * @return From 95d1fe2056467160b5b0e7517950b7204f516b7d Mon Sep 17 00:00:00 2001 From: Zhang Hai Peng Date: Tue, 2 Jun 2026 10:23:43 +0800 Subject: [PATCH 6/9] docs(bt): clarify GATT client auth_req may trigger SMP (cherry picked from commit 43734e7d7be22328135918edf2e8075c1fb717c6) Co-authored-by: zhanghaipeng --- .../host/bluedroid/api/include/api/esp_gatt_defs.h | 13 +++++++++---- .../host/bluedroid/api/include/api/esp_gattc_api.h | 4 +++- 2 files changed, 12 insertions(+), 5 deletions(-) diff --git a/components/bt/host/bluedroid/api/include/api/esp_gatt_defs.h b/components/bt/host/bluedroid/api/include/api/esp_gatt_defs.h index b8051625eef..03ba9a01624 100644 --- a/components/bt/host/bluedroid/api/include/api/esp_gatt_defs.h +++ b/components/bt/host/bluedroid/api/include/api/esp_gatt_defs.h @@ -361,10 +361,15 @@ typedef struct { /** * @brief Defines the GATT authentication request types. * - * This enumeration lists the types of authentication requests that can be made. - * It corresponds to the `BTA_GATT_AUTH_REQ_xxx` values defined in `bta/bta_gatt_api.h`. - * The types include options for no authentication, unauthenticated encryption, authenticated encryption, - * and both signed versions with and without MITM (Man-In-The-Middle) protection. + * Used as the `auth_req` argument in GATT client read/write APIs. It specifies the + * link security level required before the ATT request is sent, and is independent + * of server-side attribute permission flags (`ESP_GATT_PERM_xxx`). + * + * @note If `auth_req` is not `ESP_GATT_AUTH_REQ_NONE`, the stack may start link + * encryption or SMP pairing before the GATT operation. Handle + * `ESP_GAP_BLE_PASSKEY_REQ_EVT` and call `esp_ble_passkey_reply()` if needed. + * + * Corresponds to the `BTA_GATT_AUTH_REQ_xxx` values defined in `bta/bta_gatt_api.h`. */ typedef enum { ESP_GATT_AUTH_REQ_NONE = 0, /*!< No authentication required. Corresponds to BTA_GATT_AUTH_REQ_NONE. */ diff --git a/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h b/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h index 9f662b6c97c..65979ba4abf 100644 --- a/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h +++ b/components/bt/host/bluedroid/api/include/api/esp_gattc_api.h @@ -874,12 +874,14 @@ esp_err_t esp_ble_gattc_read_char_descr (esp_gatt_if_t gattc_if, * @param[in] value_len The length of the value to write in bytes * @param[in] value The value to write * @param[in] write_type The type of Attribute write operation - * @param[in] auth_req Authentication request type + * @param[in] auth_req Authenticate request type * * @note * 1. This function triggers `ESP_GATTC_WRITE_CHAR_EVT`. * 2. This function should be called only after the connection has been established. * 3. `handle` must be greater than 0. + * 4. If `auth_req` is not `ESP_GATT_AUTH_REQ_NONE`, the stack may start encryption + * or SMP pairing before sending the ATT write. * * @return * - ESP_OK: Success From 14b2d9fda25b926de3a365027806897c63a668a4 Mon Sep 17 00:00:00 2001 From: Zhang Hai Peng Date: Tue, 2 Jun 2026 10:23:44 +0800 Subject: [PATCH 7/9] docs(bt): clarify BLE TX power priority and granularity (cherry picked from commit 4ab49f267b5cd6905b3536d21b1e9cededea7ed4) Co-authored-by: zhanghaipeng --- .../api/include/api/esp_gap_ble_api.h | 10 ++++++- .../bt/include/esp32c3/include/esp_bt.h | 28 +++++++++++++++++-- 2 files changed, 35 insertions(+), 3 deletions(-) diff --git a/components/bt/host/bluedroid/api/include/api/esp_gap_ble_api.h b/components/bt/host/bluedroid/api/include/api/esp_gap_ble_api.h index 4fc217c36c4..4e2711324ad 100644 --- a/components/bt/host/bluedroid/api/include/api/esp_gap_ble_api.h +++ b/components/bt/host/bluedroid/api/include/api/esp_gap_ble_api.h @@ -984,7 +984,15 @@ typedef struct { esp_ble_addr_type_t peer_addr_type; /*!< ext adv peer address type */ esp_bd_addr_t peer_addr; /*!< ext adv peer address */ esp_ble_adv_filter_t filter_policy; /*!< ext adv filter policy */ - int8_t tx_power; /*!< ext adv tx power */ + int8_t tx_power; /*!< ext adv tx power. + For this advertising set, priority is higher than + `esp_ble_tx_power_set()`, `esp_ble_tx_power_set_enhanced()`, + and menuconfig default TX power (`CONFIG_BT_CTRL_DFT_TX_POWER_LEVEL`). + The actual applied TX power may be different from the requested value, + depending on the Controller TX power granularity/level mechanism. + (for example ESP32-C3/ESP32-S3 with 3 dBm step), the actual + applied TX power may be rounded down and be 0 to 2 dBm lower + than the requested value.) */ esp_ble_gap_pri_phy_t primary_phy; /*!< ext adv primary phy */ uint8_t max_skip; /*!< ext adv maximum skip */ esp_ble_gap_phy_t secondary_phy; /*!< ext adv secondary phy. diff --git a/components/bt/include/esp32c3/include/esp_bt.h b/components/bt/include/esp32c3/include/esp_bt.h index 941df1925bd..64074c1b717 100644 --- a/components/bt/include/esp32c3/include/esp_bt.h +++ b/components/bt/include/esp32c3/include/esp_bt.h @@ -539,7 +539,8 @@ typedef enum { * After disconnecting, the corresponding TX power will not be affected. * 2. `ESP_BLE_PWR_TYPE_DEFAULT` can be used to set the TX power for power types that have not been set before. * It will not affect the TX power values which have been set for the ADV/SCAN/CONN0-8 power types. - * 3. If none of power type is set, the system will use `ESP_PWR_LVL_P3` as default for all power types. + * 3. If no runtime TX power is configured, the system uses the menuconfig default + * TX power (`CONFIG_BT_CTRL_DFT_TX_POWER_LEVEL`) for all power types. */ typedef enum { ESP_BLE_PWR_TYPE_CONN_HDL0 = 0, /*!< TX power for Connection state handle 0 */ @@ -802,7 +803,19 @@ void esp_bt_controller_wakeup_request(void); * * It is recommended to use `esp_ble_tx_power_set_enhanced` to set TX power for individual advertising and connection handle. * - * @note Connection TX power should only be set after the connection is established. + * @note + * 1. Connection TX power should only be set after the connection is established. + * 2. Priority from high to low: + * - ADV TX power in `esp_ble_gap_ext_adv_set_params()`. + * - TX power configured by `esp_ble_tx_power_set_enhanced()` / `esp_ble_tx_power_set()`. + * - Menuconfig default TX power (`CONFIG_BT_CTRL_DFT_TX_POWER_LEVEL`). + * 3. If TX power is not configured through `esp_ble_gap_ext_adv_set_params()`, + * `esp_ble_tx_power_set_enhanced()`, or `esp_ble_tx_power_set()`, + * the menuconfig default TX power is applied globally. + * 4. On ESP32-C3/ESP32-S3, Controller TX power resolution is 3 dBm per step. + * The actual applied TX power may be 0 to 2 dBm lower than requested. + * For example, request 0 dBm -> apply 0 dBm; request 1/2 dBm -> apply 0 dBm; + * request 3 dBm -> apply 3 dBm. * * @param[in] power_type The type of TX power. It could be Advertising, Connection, or Default. * @param[in] power_level Power level (index) corresponding to the absolute value (dBm) @@ -842,6 +855,17 @@ esp_power_level_t esp_ble_tx_power_get(esp_ble_power_type_t power_type); * * @note * 1. Connection TX power should only be set after connection created. + * 2. Priority from high to low: + * - ADV TX power in `esp_ble_gap_ext_adv_set_params()`. + * - TX power configured by `esp_ble_tx_power_set_enhanced()` / `esp_ble_tx_power_set()`. + * - Menuconfig default TX power (`CONFIG_BT_CTRL_DFT_TX_POWER_LEVEL`). + * 3. If TX power is not configured through `esp_ble_gap_ext_adv_set_params()`, + * `esp_ble_tx_power_set_enhanced()`, or `esp_ble_tx_power_set()`, + * the menuconfig default TX power is applied globally. + * 4. On ESP32-C3/ESP32-S3, Controller TX power resolution is 3 dBm per step. + * The actual applied TX power may be 0 to 2 dBm lower than requested. + * For example, request 0 dBm -> apply 0 dBm; request 1/2 dBm -> apply 0 dBm; + * request 3 dBm -> apply 3 dBm. * * @param[in] power_type The type of TX power * @param[in] handle The handle of Advertising or Connection From 5b5a6209ce70035f7c75c83e9d659536768b4703 Mon Sep 17 00:00:00 2001 From: Zhang Hai Peng Date: Tue, 2 Jun 2026 10:24:03 +0800 Subject: [PATCH 8/9] fix(ble/bluedroid): Validate signed-write perm vs AUTH in attr table check (cherry picked from commit fce3fa337af6653febb055cb41d1a75b7d7098ef) Co-authored-by: zhanghaipeng --- .../host/bluedroid/btc/profile/std/gatt/btc_gatts.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/components/bt/host/bluedroid/btc/profile/std/gatt/btc_gatts.c b/components/bt/host/bluedroid/btc/profile/std/gatt/btc_gatts.c index 6f9f50d3bd4..8594a490574 100644 --- a/components/bt/host/bluedroid/btc/profile/std/gatt/btc_gatts.c +++ b/components/bt/host/bluedroid/btc/profile/std/gatt/btc_gatts.c @@ -560,6 +560,19 @@ static esp_gatt_status_t btc_gatts_check_valid_attr_tab(esp_gatts_attr_db_t *gat return ESP_GATT_INVALID_PDU; } } + + /* Same rule as GATTS_AddCharacteristic(): signed-write perm requires AUTH property */ + { + uint8_t char_property = (uint8_t)(*(uint8_t *)(gatts_attr_db[i].att_desc.value)); + uint16_t perm = gatts_attr_db[i + 1].att_desc.perm; + + if (((char_property & GATT_CHAR_PROP_BIT_AUTH) && !(perm & GATT_WRITE_SIGNED_PERM)) || + ((perm & GATT_WRITE_SIGNED_PERM) && !(char_property & GATT_CHAR_PROP_BIT_AUTH))) { + BTC_TRACE_ERROR("%s, Invalid char property=0x%02x perm=0x%04x at table index %d", + __func__, char_property, perm, i); + return ESP_GATT_ILLEGAL_PARAMETER; + } + } break; default: break; From 427d82e114ed1a1c6d332a27d8e2a6a5a097e1ee Mon Sep 17 00:00:00 2001 From: Zhang Hai Peng Date: Tue, 2 Jun 2026 10:24:03 +0800 Subject: [PATCH 9/9] fix(ble/bluedroid): Propagate create_attr_tab BTA failures in inter_cb (cherry picked from commit 4f8027da116364447b52e513b77ed34c72c54577) Co-authored-by: zhanghaipeng --- .../btc/profile/std/gatt/btc_gatts.c | 56 +++++++++++-------- 1 file changed, 34 insertions(+), 22 deletions(-) diff --git a/components/bt/host/bluedroid/btc/profile/std/gatt/btc_gatts.c b/components/bt/host/bluedroid/btc/profile/std/gatt/btc_gatts.c index 8594a490574..af060c80b65 100644 --- a/components/bt/host/bluedroid/btc/profile/std/gatt/btc_gatts.c +++ b/components/bt/host/bluedroid/btc/profile/std/gatt/btc_gatts.c @@ -658,43 +658,55 @@ static void btc_gatts_inter_cb(tBTA_GATTS_EVT event, tBTA_GATTS *p_data) msg.sig = BTC_SIG_API_CB; msg.pid = BTC_PID_GATTS; msg.act = event; - if(btc_creat_tab_env.is_tab_creat_svc && btc_creat_tab_env.complete_future) { - switch(event) { - case BTA_GATTS_CREATE_EVT: { - //save the service handle to the btc module after used - //the attribute table method to creat a service + if (btc_creat_tab_env.is_tab_creat_svc && btc_creat_tab_env.complete_future) { + void *result = FUTURE_SUCCESS; + uint16_t index = btc_creat_tab_env.handle_idx; + + switch (event) { + case BTA_GATTS_CREATE_EVT: + if (p_data->create.status != BTA_GATT_OK || p_data->create.service_id == 0) { + result = FUTURE_FAIL; + } else { + /* save the service handle after the attribute table method creates a service */ bta_to_btc_uuid(&btc_creat_tab_env.svc_uuid, &p_data->create.uuid); - uint16_t index = btc_creat_tab_env.handle_idx; btc_creat_tab_env.svc_start_hdl = p_data->create.service_id; btc_creat_tab_env.handles[index] = p_data->create.service_id; - break; } - case BTA_GATTS_ADD_INCL_SRVC_EVT: { - uint16_t index = btc_creat_tab_env.handle_idx; + break; + case BTA_GATTS_ADD_INCL_SRVC_EVT: + if (p_data->add_result.status != BTA_GATT_OK || p_data->add_result.attr_id == 0) { + result = FUTURE_FAIL; + } else { btc_creat_tab_env.handles[index] = p_data->add_result.attr_id; - break; } - case BTA_GATTS_ADD_CHAR_EVT: { - uint16_t index = btc_creat_tab_env.handle_idx; + break; + case BTA_GATTS_ADD_CHAR_EVT: + if (p_data->add_result.status != BTA_GATT_OK || p_data->add_result.attr_id == 0) { + result = FUTURE_FAIL; + } else { btc_creat_tab_env.handles[index] = p_data->add_result.attr_id - 1; if (index + 1 < btc_creat_tab_env.num_handle) { - btc_creat_tab_env.handles[index+1] = p_data->add_result.attr_id; + btc_creat_tab_env.handles[index + 1] = p_data->add_result.attr_id; } else { - BTC_TRACE_ERROR("%s handles[%d+1] out of bounds (num_handle=%d)", - __func__, index, btc_creat_tab_env.num_handle); + result = FUTURE_FAIL; } - break; } - case BTA_GATTS_ADD_CHAR_DESCR_EVT: { - uint16_t index = btc_creat_tab_env.handle_idx; + break; + case BTA_GATTS_ADD_CHAR_DESCR_EVT: + if (p_data->add_result.status != BTA_GATT_OK || p_data->add_result.attr_id == 0) { + result = FUTURE_FAIL; + } else { btc_creat_tab_env.handles[index] = p_data->add_result.attr_id; - break; } - default: - break; + break; + default: + break; } - future_ready(btc_creat_tab_env.complete_future, FUTURE_SUCCESS); + if (result == FUTURE_FAIL) { + BTC_TRACE_ERROR("%s create_attr_tab failed, event=%d", __func__, event); + } + future_ready(btc_creat_tab_env.complete_future, result); return; } status = btc_transfer_context(&msg, p_data, sizeof(tBTA_GATTS),